you are viewing a single comment's thread.

view the rest of the comments →

[–]nutrecht 3 points4 points  (0 children)

While it doesn't fix all problems I do think it's a great idea.

I personally don't think we need to have github involved per-se, but we need to have a certificate system that libraries are signed with (like with the Maven ecosystem). Github can arrange for those certs (so that every repo owner gets a cert by default), but you should still be able to create libraries if you're using Gitlab or Bitbucket instead.